Skip to Content

Incident Reporting Rules Scheduled to Be Released in September

on Tuesday, 28 July 2026 in Technology & Intellectual Property Update: Arianna C. Goldstein, Editor

According to the unified regulatory agenda published on July 3, the Cybersecurity and Infrastructure Security Agency (“CISA”) is expected to finalize long-awaited incident reporting rules for critical infrastructure. The agenda states that CISA will finalize regulations implementing certain aspects of the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (“CIRCIA”) by September.

CIRCIA, enacted in March 2022 as part of broader federal appropriations legislation, directed CISA to require critical infrastructure sectors to report significant cyber incidents and ransomware payments. In April 2024, CISA issued a Notice of Proposed Rulemaking (“NPRM”) proposing criteria for identifying “covered entities” and requirements for reportable incidents and ransom payment reports. CISA missed CIRCIA’s October 2025 statutory deadline and later set a May 2026 internal target, citing extensive comments and a goal of streamlining the rule.

The two primary issues to be resolved by the final rule include:

Qualification as a Covered Entity. In a February request for information, CISA sought input on which organizations should qualify as covered entities, including thresholds based on size, revenue, operational significance, or a critical role in national security, public health, economic stability, or other essential functions.

Substantial Cyber Incident Threshold. CISA also sought input on what should qualify as a “substantial cyber incident,” including whether the threshold should depend on operational disruption, financial loss, public safety impacts, compromised sensitive data, or reduced availability of critical services.

Under the proposed rule, a “substantial cyber incident” is defined as one resulting in any of the following:

  1. Substantial loss of confidentiality, integrity, or availability of an information system or network.
  2. Serious impact on operational system or process safety or resilience.
  3. Disruption to business or industrial operations, or to providing goods or services.
  4. Unauthorized access through a compromised cloud, managed service, third-party hosting provider, or supply chain.

We will continue to monitor the CISA website for further CIRCIA developments as the rule moves toward finalization.

1700 Farnam Street | Suite 1500 | Omaha, NE 68102 | 402.344.0500

Law Firm Website Design